Legal
Privacy Policy
Last updated: August 2, 2026
This Privacy Policy explains how Jorora (“we”, “us”) processes personal data when you use our websites and the AI Freight Invoice Validator (the “Service”).
1. Controller
For users in Colombia and internationally, the data controller is the operator of Jorora as identified in the Service footer / account notices. Contact: the support email published in the product (or the email used for your account communications).
2. Data we process
- Account data: name, email, organization name, authentication metadata.
- Billing data: plan, credit balance, Stripe customer/checkout identifiers (card data is handled by Stripe; we do not store full card numbers).
- Documents you upload: carrier invoices, rate confirmations, PODs, BOLs, lumper receipts and extracted fields needed to run validations.
- Usage data: validations, decisions, rule outcomes, audit logs, technical logs.
- Device / site data: cookies or similar technologies as described in our Cookie Policy.
3. Purposes and legal bases
We process data to:
- Provide the Service and consume credits (contract / pre-contractual measures).
- Secure accounts, prevent abuse, and debug failures (legitimate interests / legal duty).
- Comply with tax, accounting, and consumer obligations where applicable.
- Improve extraction quality using aggregated or de-identified signals where lawful.
If GDPR/UK GDPR or similar regimes apply to you, the legal bases are typically contract, legitimate interests, legal obligation, and consent where required (e.g. non-essential cookies).
4. AI processing
Document fields may be processed by AI extraction providers (currently configured OpenAI models) solely to extract structured data for validation. Do not upload documents you are not authorized to process. See the AI Disclaimer.
5. Sharing
We share data with processors that help us operate the Service, such as:
- Hosting / database (e.g. Vercel, Neon/Postgres).
- Email delivery (e.g. Resend).
- Payments (Stripe).
- AI extraction providers under contractual data processing terms.
We do not sell personal data.
6. International transfers
Infrastructure and processors may be located outside your country (including the United States). Where required, we rely on appropriate transfer mechanisms (e.g. SCCs) as implemented by those processors.
7. Retention
Account and billing records are kept while your account is active and as required by law. Uploaded documents and validation artifacts are retained to provide history according to your plan limits and operational needs, then deleted or anonymized according to our retention schedule. You may request deletion subject to legal holds.
8. Security
We use access controls, encrypted transport (TLS), tenant isolation by organization, and least-privilege practices. No method of transmission or storage is perfectly secure.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of personal data, and to object or withdraw consent. Colombian users may exercise habeas data rights under applicable Colombian data-protection rules. EU/EEA users may lodge a complaint with a supervisory authority. California residents may have CCPA/CPRA rights; Brazil residents may have LGPD rights. Contact us to exercise rights.
10. Children
The Service is for business users and is not directed to children under 18.
11. Changes
We may update this Policy. Material changes will be posted with a new “Last updated” date.
These templates are provided for product launch readiness. They are not legal advice. Engage qualified counsel licensed in Colombia (and in any other jurisdiction where you market or sell) before relying on them commercially.